What is CVE-2026-48558?
CVE-2026-48558 is an authentication bypass vulnerability in the OIDC authentication flow of SimpleHelp. It allows remote, unauthenticated attackers to gain access by using identity tokens that are accepted without verifying their cryptographic signature. Applying the security update on affected SimpleHelp instances is strongly recommended.
Azərbaycanca: CVE-2026-48558 SimpleHelp proqramında OIDC autentifikasiya axınında aşkar edilmiş autentifikasiyadan yayınma zəifliyidir. Bu boşluq uzaqdan gələn, autentifikasiya olunmamış hücumçuya rəqəmsal imza yoxlanılmadan qəbul edilən identiklik tokenləri ilə sistemə giriş imkanı verir. Təsirə məruz qalan SimpleHelp qurğularında təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ1
What does the authentication bypass vulnerability in SimpleHelp (CVE-2026-48558) allow via identity tokens?
CVE-2026-48558 allows remote, unauthenticated attackers to gain access to a SimpleHelp instance by using identity tokens that are accepted without verifying their cryptographic signature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.